Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Unclassified CRITICAL 9.8
CVE-2025-61260EPSS 7%

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) conf…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified MEDIUM 6.5
CVE-2026-2582

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions…

Mitigation only
Fix from $1,600 2026-04-14
Praisonaiagents CRITICAL 9.8
CVE-2026-40288

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to …

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Praisonaiagents HIGH 8.4
CVE-2026-40287

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import …

Fix: 1.5.140 / 4.5.139+
Fix from $1,950 2026-04-14
Maxkb HIGH 7.4
CVE-2026-39421

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. B…

Fix: 2.8.0+
Fix from $1,950 2026-04-14
Netweaver Application Server Java MEDIUM 6.1
CVE-2026-27674

Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted in…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified HIGH 8.8
CVE-2025-51414

In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality …

Mitigation only
Fix from $1,950 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-31048

An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.

Mitigation only
Fix from $2,300 2026-04-13
Kubeplus HIGH 8.8
CVE-2026-29955

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.…

Fix: after 4.2.0
Fix from $1,950 2026-04-13
Unclassified MEDIUM 6.3
CVE-2026-6125

A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save…

Mitigation only
Fix from $1,600 2026-04-12
Metagpt CRITICAL 9.8
CVE-2026-6110

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.…

Patch available
Fix from $2,300 2026-04-12
Praisonai HIGH 7.8
CVE-2026-40156

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to …

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Praisonai HIGH 7.8
CVE-2026-40158

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampolin…

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Litellm HIGH 8.8
CVE-2026-40217EPSS 6%

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Fix: after 2026-04-08
Fix from $1,950 2026-04-10
Metagpt CRITICAL 9.8
CVE-2026-5970

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB…

Fix: after 0.8.1
Fix from $2,300 2026-04-09
Metagpt CRITICAL 9.8
CVE-2026-5971

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action…

Fix: after 0.8.1
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.1
CVE-2026-30479

A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted execut…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified HIGH 8.8
CVE-2025-70364

An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Su…

Mitigation only
Fix from $1,950 2026-04-09
Unclassified HIGH 7.2
CVE-2024-1490

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If …

Mitigation only
Fix from $1,950 2026-04-09
GitLab MEDIUM 5.7
CVE-2026-1516

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Co…

Fix: 18.8.9 / 18.9.5+
Fix from $1,600 2026-04-08
Praisonai HIGH 8.8
CVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that proces…

Fix: after 4.5.114
Fix from $1,950 2026-04-08
Vim HIGH 7.8
CVE-2026-39881

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious …

Fix: 9.2.0316+
Fix from $1,950 2026-04-08
Zammad HIGH 7.2
CVE-2026-34724

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RC…

Mitigation only
Fix from $1,950 2026-04-08
Stata Mcp CRITICAL 9.8
CVE-2026-31040

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command…

Fix: 1.13.0+
Fix from $2,300 2026-04-08
Movable Type CRITICAL 9.8
CVE-2026-25776

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Fix: 8.0.10 / 8.8.3+
Fix from $2,300 2026-04-08
Siyuan CRITICAL 9.0
CVE-2026-39846

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si…

Fix: 3.6.4+
Fix from $2,300 2026-04-07
Unclassified HIGH 7.3
CVE-2026-5739

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi…

Mitigation only
Fix from $1,950 2026-04-07
Unclassified CRITICAL 9.1
CVE-2025-71058

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configure…

No fix yet
Fix from $2,300 2026-04-07
Churchcrm CRITICAL 10.0
CVE-2026-39337

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's …

Fix: 7.1.0+
Fix from $2,300 2026-04-07
Yaffa MEDIUM 6.1
CVE-2025-70844

yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the ac…

Mitigation only
Fix from $1,600 2026-04-07